---
id: CVE-2026-31420
title: 'bridge: mrp: reject zero test interval to avoid OOM panic'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  bridge: mrp: reject zero test interval to avoid OOM panic

  br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied
  interval value from netlink without v…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    610073ffb77ffd2b5eca182d2ac264de4834a175
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    ec8850be9b2b3beac1c7967d95f169dd2785979d
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    1ec86b4b9e28170a2565cf36f0e6e2b96b55134d
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    2120bd8546cd6a63c558d135773aa8f41c8259fc
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    630a15a31c2034b5b697f4aabc769b9d80d82446
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    e8ec80430bfa520e7352155d6ac632e527cba7aa
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    c9bc352f716d1bebfe43354bce539ec2d0223b30
  - >-
    Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d <
    fa6e24963342de4370e3a3c9af41e38277b74cf3
  - Linux 5.8
published: '2026-04-13'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:16.075Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-31420'
references:
  - url: 'https://git.kernel.org/stable/c/610073ffb77ffd2b5eca182d2ac264de4834a175'
  - url: 'https://git.kernel.org/stable/c/ec8850be9b2b3beac1c7967d95f169dd2785979d'
  - url: 'https://git.kernel.org/stable/c/1ec86b4b9e28170a2565cf36f0e6e2b96b55134d'
  - url: 'https://git.kernel.org/stable/c/2120bd8546cd6a63c558d135773aa8f41c8259fc'
  - url: 'https://git.kernel.org/stable/c/630a15a31c2034b5b697f4aabc769b9d80d82446'
  - url: 'https://git.kernel.org/stable/c/e8ec80430bfa520e7352155d6ac632e527cba7aa'
  - url: 'https://git.kernel.org/stable/c/c9bc352f716d1bebfe43354bce539ec2d0223b30'
  - url: 'https://git.kernel.org/stable/c/fa6e24963342de4370e3a3c9af41e38277b74cf3'
tags:
  - cve.org
epss: 0.00125
epssPercentile: 0.019
ingestedAt: '2026-09-14T15:23:07.459Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

bridge: mrp: reject zero test interval to avoid OOM panic

br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied
interval value from netlink without validation. When interval is 0,
usecs_to_jiffies(0) yields 0, causing the delayed work
(br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule
itself with zero delay. This creates a tight loop on system_percpu_wq
that allocates and transmits MRP test frames at maximum rate, exhausting
all system memory and causing a kernel panic via OOM deadlock.

The same zero-interval issue applies to br_mrp_start_in_test_parse()
for interconnect test frames.

Use NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both
IFLA_BRIDGE_MRP_START_TEST_INTERVAL and
IFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the
netlink attribute parsing layer before the value ever reaches the
workqueue scheduling code. This is consistent with how other bridge
subsystems (br_fdb, br_mst) enforce range constraints on netlink
attributes.

## Affected

- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 610073ffb77ffd2b5eca182d2ac264de4834a175`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < ec8850be9b2b3beac1c7967d95f169dd2785979d`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 1ec86b4b9e28170a2565cf36f0e6e2b96b55134d`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 2120bd8546cd6a63c558d135773aa8f41c8259fc`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < 630a15a31c2034b5b697f4aabc769b9d80d82446`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < e8ec80430bfa520e7352155d6ac632e527cba7aa`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < c9bc352f716d1bebfe43354bce539ec2d0223b30`
- `Linux >= 20f6a05ef63594feb0c6dfbd629da0448b43124d < fa6e24963342de4370e3a3c9af41e38277b74cf3`
- `Linux 5.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
